ShinyHunters defaces Clop's leak site and claims its onion keys — a cybercrime feud, and what's actually confirmed
By Sethu Satheesh · 21 Sept 2026 · 10 min read
Threat Actor: ShinyHunters (self-identified extortion group) · Target: The Clop (Cl0p) ransomware operation's Tor data leak site
Source: www.bleepingcomputer.com
Executive Summary
On the night of Friday, September 19, 2026, the extortion group ShinyHunters breached and defaced the Tor-based data leak site of the Clop (Cl0p) ransomware operation — one cybercrime brand publicly humiliating another.123 BleepingComputer independently confirmed the two observable facts: an initial text file uploaded to Clop's server ("THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p — Maybe don't try to threaten us next time"), downloadable directly from Clop's onion site, and, hours later, the wholesale replacement of the leak site with ASCII art of Umbreon — the Pokémon ShinyHunters uses as its logo — above the line "rooting your systems since '19 ;)".1
Everything beyond the defacement rests on ShinyHunters' own account. The group told BleepingComputer it exploited "what they claim is an unauthenticated file upload vulnerability in Grav CMS" to plant the file, then gained "full access" to the server and stole the leak site's source code, Grav CMS plugins, and system logs — including everything under /var/log, which it noted could contain authentication records and the IP addresses of visitors to Clop's site.1 Most consequentially, ShinyHunters claims to have obtained the private keys to Clop's Tor onion service: "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL."1 If those keys are genuine, ShinyHunters could stand up a site at Clop's own onion address on infrastructure it controls. BleepingComputer states plainly that it has independently confirmed the defacement and the uploaded file but has not verified the claimed theft of source code, logs, or onion keys.1
The motive is a cybercrime feud with a concrete origin. ShinyHunters says the attack is retaliation for threats made by a Clop representative during a dispute dating to Clop's 2025 Oracle E-Business Suite data-theft campaign — in which Clop exploited multiple Oracle EBS vulnerabilities, including the zero-day CVE-2025-61882, for mass extortion.1 Around that campaign, actors calling themselves "Scattered Lapsus$ Hunters" (including ShinyHunters) leaked a proof-of-concept exploit that Oracle later confirmed matched the one used in the Clop attacks; ShinyHunters says the exploit was originally theirs and that Clop had taken it without authorization.1 ShinyHunters alleges a Clop representative then messaged it directly with a death threat (translated from Russian: "I have more money than you and all of your people combined, I'll kill you soon").1 ShinyHunters says it now intends to extort Clop, giving the gang 72 hours to make contact.1
For a defensive publication, the value here is precisely in the gap between what is provable and what is asserted, by an actor whose entire business is making claims about data it holds. The defacement is real and independently confirmed; the data theft and the onion-key claim — the parts that would actually matter to Clop's victims and to Clop itself — are, so far, only ShinyHunters' word.
Verification of Claims
-
Claim: ShinyHunters defaced Clop's Tor leak site. → Verified → BleepingComputer independently confirmed both the initial uploaded file (downloadable from Clop's onion site) and the full defacement with ShinyHunters' Umbreon artwork.1
-
Claim: ShinyHunters obtained the private keys to Clop's Tor onion service. → Unverified → This is ShinyHunters' claim; BleepingComputer states it has not independently verified it. If genuine, the keys would let ShinyHunters operate a site at Clop's existing onion address.1
-
Claim: ShinyHunters stole Clop's leak-site source code and
/var/logsystem logs. → Unverified → Also ShinyHunters' claim, explicitly not independently verified; only the defacement and uploaded file are confirmed.1 -
Claim: The breach used an unauthenticated file-upload vulnerability in Grav CMS. → Weak evidence → BleepingComputer describes this as "what they claim." The compromise itself is proven by the confirmed defacement, but the specific entry vector is the attacker's account, uncorroborated.1
-
Claim: The Umbreon defacement art ties this to ShinyHunters' earlier activity. → Assessed → Researcher VXDB told BleepingComputer the Umbreon artwork matches the August 2020 defacement of HackForums, which ShinyHunters also claimed at the time.1
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| October 2025 | Clop | Exploits Oracle E-Business Suite vulnerabilities, including zero-day CVE-2025-61882, for mass data-theft extortion | 1 |
| Around October 2025 | Scattered Lapsus$ Hunters / ShinyHunters | Leak a PoC exploit Oracle later confirmed matched the Clop attacks; ShinyHunters says the exploit was originally theirs | 1 |
| September 19, 2026 (Friday night) | ShinyHunters | Uploads a taunting text file to Clop's leak site via a claimed Grav CMS file-upload flaw; BleepingComputer confirms the file on Clop's server | 1 |
| September 19, 2026 (hours later) | ShinyHunters | Fully defaces Clop's leak site with Umbreon artwork; claims theft of source code, logs and onion keys; sets a 72-hour extortion deadline | 1 |
Attack Anatomy
The only stage independently confirmed is the defacement; the access and theft steps are ShinyHunters' account, presented here as such.
Initial access — claimed Grav CMS file upload
ShinyHunters says it exploited an unauthenticated file upload vulnerability in Grav CMS — the flat-file content-management system running Clop's leak site — to upload a text file to the server (T1190).1 BleepingComputer confirmed the file was present on Clop's server and downloadable from the onion site.1
Escalation and control — claimed full server access
From that foothold, ShinyHunters claims it gained "full access" to the server (T1505.003), the level of control consistent with its ability to then replace the site entirely.1
Data theft — claimed
ShinyHunters says it stole the leak site's source code, Grav CMS plugins, and all files under /var/log — potentially including authentication logs and visitor IP addresses (T1213) — and, critically, the private keys for Clop's Tor onion service (T1552.004).1 None of this is independently verified.1
Defacement and extortion — confirmed defacement
ShinyHunters replaced Clop's leak site with Umbreon ASCII art and a taunt (T1491.002), and stated it will publish a message on its own leak site giving Clop 72 hours to make contact before it acts on the stolen data (T1657).1
Loading diagram...
Threat Actor Profile
- Attacker: ShinyHunters — a long-running data-theft and extortion group, self-identified in the defacement and in direct statements to BleepingComputer.1 The "rooting your systems since '19 ;)" tagline and the reused Umbreon artwork (matching a 2020 HackForums defacement) are consistent with the group's history.1
- Victim: the Clop (Cl0p) ransomware operation — itself a prolific extortion actor, most recently behind the October 2025 Oracle E-Business Suite mass-exploitation campaign.1
- Motivation: retaliation and extortion. ShinyHunters frames the attack as payback for an alleged death threat from a Clop representative amid a dispute over ownership of the Oracle EBS exploit, and states it now intends to extort Clop.1
- Attribution confidence: The attacker is self-identified and the defacement is confirmed, so ShinyHunters' authorship of the defacement is well supported. Its claims about what it stole are uncorroborated. Clop had not responded to BleepingComputer's request for comment at publication.1
MITRE ATT&CK techniques (the entry vector and theft steps reflect ShinyHunters' claims; only the defacement is confirmed):
| ID | Technique |
|---|---|
| T1190 | Exploit Public-Facing Application |
| T1505.003 | Server Software Component: Web Shell |
| T1213 | Data from Information Repositories |
| T1552.004 | Unsecured Credentials: Private Keys |
| T1491.002 | Defacement: External Defacement |
| T1657 | Financial Theft |
Technical Indicators
# This is a defacement-and-extortion incident against a criminal site; there is
# no defender-actionable malicious infrastructure to block. Artifacts are the
# attacker's own messaging and the claimed entry point.
victim: "Clop (Cl0p) ransomware data leak site (Tor onion service)"
software_named: "Grav CMS (flat-file CMS running the leak site)"
claimed_entry_vector: "unauthenticated file upload vulnerability in Grav CMS (attacker's claim)"
defacement_marker: "Umbreon ASCII art + 'rooting your systems since 19 ;)' (confirmed)"
uploaded_file_text: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p (confirmed on Clop server)"
claimed_stolen:
- "leak site source code and Grav CMS plugins (unverified)"
- "/var/log system logs, possibly incl. auth logs and visitor IPs (unverified)"
- "Tor onion service private keys (unverified)"
network_iocs: none applicable
file_hashes: none disclosedLegal and Regulatory Response
None. Both parties are criminal operations, and no law-enforcement action tied to this specific defacement has been reported. The broader backdrop includes Oracle's October 2025 confirmation that the leaked proof-of-concept matched the exploit (CVE-2025-61882) used in Clop's Oracle E-Business Suite campaign — the dispute ShinyHunters cites as the origin of the feud.1
Impact Assessment
- Confirmed: Clop's Tor leak site was defaced by ShinyHunters; an initial taunt file was planted on Clop's server and was downloadable from the onion site.1
- Claimed, unverified: Theft of the leak site's source code, Grav CMS plugins,
/var/loglogs (possibly including authentication data and visitor IP addresses), and the Tor onion service's private keys.1 - Potential significance if the onion-key claim is true: ShinyHunters could host a site at Clop's existing onion address, undermining the integrity of Clop's leak-site brand and any victim negotiations conducted through it.1
- Unknown: Whether Clop's operations, victim negotiations, or previously leaked victim data are affected; whether Clop can regain control; and whether ShinyHunters' data-theft claims hold up. Clop had not responded at publication.1
Lessons and Defensive Recommendations
For threat intelligence and IR teams tracking these actors:
- Treat the defacement as confirmed and the data-theft/onion-key claims as unverified attacker assertions until corroborated. Extortion actors have a standing incentive to overstate what they hold; a leak-site takeover is highly visible, but "we have their onion keys and all their logs" is exactly the sort of claim that shapes rival-actor dynamics regardless of whether it is true.
- If ShinyHunters'
/var/logclaim were accurate, the most sensitive downstream exposure is not Clop's but that of visitors to Clop's leak site — journalists, researchers, victims, and negotiators whose connection metadata could sit in those logs. Assess that exposure independently of ShinyHunters' extortion narrative.
For defenders generally (the reusable technical lesson):
- The claimed entry vector is a mundane one: an unauthenticated file-upload flaw in a CMS. Whether or not it is the true vector here, unauthenticated file upload remains a top cause of web-server compromise. Enforce authentication on upload endpoints, validate file type and content server-side, store uploads outside the web root, and never trust a flat-file CMS deployment to be hardened by default.
For readers of cybercrime-on-cybercrime stories:
- Infighting between extortion brands is genuinely newsworthy, but the reporting standard should not drop just because the victim is itself a criminal group. The confirmed facts (a defacement) and the asserted ones (mass data and key theft) deserve to be labelled differently — which is how the original reporting handled it, and how any repetition of the story should too.
Sources
Footnotes
-
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — BleepingComputer, Lawrence Abrams, September 19, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34
-
ShinyHunters hacks Clop ransomware gang and threatens extortion — Cybernews, September 2026 ↩
-
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — DataBreaches.net, September 19, 2026 ↩
Related Research
Cl0p exploited an unauthenticated deserialization flaw in PTC Windchill as a zero-day in June 2026, deployed a purpose-built web shell that decrypts the application's keystore, and named 43 manufacturers, including Shell, Philips and GE. It was the second such flaw in three months.
ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.
A financially motivated threat actor (UNC5537) compromised Snowflake customer instances across 165+ organizations by credential stuffing against accounts lacking MFA, exfiltrating terabytes of sensitive data, and conducting mass extortion — the largest cloud data warehouse compromise to date.